Skip to content

Conversation

@tausbn
Copy link
Contributor

@tausbn tausbn commented Dec 9, 2025

See https://docs.python.org/3/library/compression.zstd.html for information about this library.

As far as I can tell, the zstd library is not vulnerable to things like ZipSlip, but it could be vulnerable to a decompression bomb attack, so I extended those models accordingly.

@github-actions github-actions bot added the Python label Dec 9, 2025
See https://docs.python.org/3/library/compression.zstd.html for
information about this library.

As far as I can tell, the `zstd` library is not vulnerable to things
like ZipSlip, but it _could_ be vulnerable to a decompression bomb
attack, so I extended those models accordingly.
@tausbn tausbn force-pushed the tausbn/python-add-models-for-zstd-compression branch from f102f9f to ad68a5e Compare December 9, 2025 22:52
@tausbn tausbn changed the title Python: Add models for zstd.compression Python: Add modelling for zstd.compression Dec 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants